Project

General

Profile

Actions

Feature #1158

closed
CB VJ

Parser DNS TXT data parsing and logging

Feature #1158: Parser DNS TXT data parsing and logging

Added by Christie Bunlon about 12 years ago. Updated almost 12 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

I am trying to detect DNS Tunneling.
For this I use the DNS logger in Suricata 2.0.
But when TXT answers have lot of data, the DNS logger say '<no data>'.


Files

dns.log (45 KB) dns.log Log DNS trafic Christie Bunlon, 04/01/2014 04:06 AM
90dns22.pcap (30.7 KB) 90dns22.pcap DNS Tunneling Trafic Christie Bunlon, 04/01/2014 04:06 AM

CB Updated by Christie Bunlon about 12 years ago Actions #1

Sorry is not the parser but the DNS logger.

VJ Updated by Victor Julien about 12 years ago Actions #2

  • Status changed from New to Assigned
  • Assignee set to Victor Julien
  • Target version set to 2.0.1rc1

I think this is only matter of extending the dns loggers. If it turns out to be more involved it will likely go into 2.1.

VJ Updated by Victor Julien almost 12 years ago Actions #3

  • Target version changed from 2.0.1rc1 to 2.0.2

VJ Updated by Victor Julien almost 12 years ago Actions #4

  • % Done changed from 0 to 50

VJ Updated by Victor Julien almost 12 years ago Actions #5

  • Tracker changed from Bug to Feature
  • Subject changed from Parser DNS no parsing TXT data to Parser DNS TXT data parsing and logging

CB Updated by Christie Bunlon almost 12 years ago Actions #6

I have tested it but it seems still not working,saying again <no data> with 90dns22.pcap

VJ Updated by Victor Julien almost 12 years ago Actions #7

I'm not getting any 'no data' with this branch, are you sure you tested the branch from pull request 967?

CB Updated by Christie Bunlon almost 12 years ago Actions #8

Sorry, i made a mistake with my suricata.

It's logging correctly the answers now.

Thank you for your help. You can close the ticket. :)

VJ Updated by Victor Julien almost 12 years ago Actions #9

  • Status changed from Assigned to Closed
  • % Done changed from 50 to 100
Actions

Also available in: PDF Atom